Administrative sanction imposed on Transnet Soc Ltd
The CSSF has published an administrative sanction dated 21 July 2026 in respect of Transnet Soc Ltd, a South African issuer with Luxembourg as home Member State under the Transparency regime. Although the notice itself is very brief, it clearly continues a pattern of enforcement against Transnet for breaches of the Luxembourg Law of 11 January 2008 on transparency requirements for issuers (Transparency Law), including a prior EUR 15,000 fine for late publication of its annual financial report. For compliance teams, this underscores the CSSF’s willingness to publicly sanction and name issuers that fail to meet periodic disclosure obligations, even for relatively modest monetary amounts.
What Changed
- As the 21 July 2026 CSSF notice is an enforcement publication (not a new rule), it does not introduce new regulatory requirements; it applies existing Transparency Law obligations.
- Issuers with Luxembourg as home Member State under the Transparency Law must publish annual financial reports within the statutory deadline, typically within four months of financial year-end, and...
- Failure to publish periodic financial information within the required time limits can result in administrative fines imposed by the CSSF under Article 25(2) of the Transparency Law.
- The CSSF will publicly disclose administrative fines imposed on issuers, including naming the issuer and the amount, in line with Article 26b of the Transparency Law.
- Issuers retain the right to challenge CSSF decisions before the Luxembourg Administrative Court within the period set by Article 27 of the Transparency Law (three months from notification), but...
Suggested Considerations
- Map all Transparency Law obligations applicable to your entity, including periodic (annual and half‑yearly) reporting and ongoing disclosure of regulated information, and document them in a compliance obligations register.
- Review and, where necessary, strengthen internal processes to ensure annual and half‑yearly financial reports are prepared, approved, and published within statutory deadlines for issuers with Luxembourg as home Member State.
- Implement a formal disclosure governance framework assigning clear responsibilities to senior management and the board for oversight of regulated information, including escalation procedures where delays or issues arise.
- Establish a calendar of regulatory reporting and publication deadlines, including internal cut‑off dates and contingency plans, and ensure it is monitored by compliance and finance functions.
- Conduct a gap analysis of prior disclosures (financial reports, major holdings notifications, inside information) to confirm that all items required under the Transparency Law have been published correctly and on time; remediate any deficiencies promptly.
Key Dates
– End of the financial year referenced in the prior CSSF sanction against Transnet Soc Ltd for failure to publish its annual financial report within the required time limit
– CSSF imposed an administrative fine of EUR 15,000 on Transnet Soc Ltd under Article 25(2) of the Transparency Law for late publication of the annual financial report as of 31 March 2021
– CSSF publishes the administrative sanction “Administrative sanction imposed on Transnet Soc Ltd”; this enforcement notice is made public in line with the Transparency Law’s publication requirements
– Statutory window during which Transnet Soc Ltd (or any sanctioned issuer) may lodge a court action against the CSSF decision with the Luxembourg Administrative Court under Article 27 of the Transparency Law
Compliance Impact
CSSF administrative fines under the Transparency Law may be modest in absolute value but carry material reputational and supervisory impact because the sanctions, the issuer’s name, and the failures are publicly disclosed. Persistent or repeated non‑compliance with transparency and disclosure obligations can trigger higher fines, closer supervisory scrutiny, and increased legal risk, including potential court actions and investor claims.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerBank Administrative sanction imposed on the members of the board of directors of an electronic money institution
The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.
What Changed
- - The CSSF demonstrates that it is prepared to impose administrative sanctions directly on members of the board of directors of electronic money institutions, not just on the institution as a legal...
- Board members of Luxembourg‑authorised electronic money institutions are now clearly exposed to personal regulatory liability for governance, risk management and safeguarding failures under the CSSF...
- This enforcement confirms that CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions and electronic money institutions is not only a formal...
- The sanction underscores CSSF expectations that the supervisory body (board of directors) must ensure sound and prudent management, continuity of the institution and protection of its reputation, and...
- The case signals a stricter enforcement posture by the CSSF towards the payments and e‑money sector, aligning its expectations and enforcement intensity more closely with bank‑equivalent governance...
Suggested Considerations
- Review and map the institution’s current governance framework, board charter and committee mandates against the detailed requirements of CSSF Circular 26/906, including central administration, board composition, responsibilities and functioning.
- Ensure that the board of directors collectively has the required expertise, independence, diversity and time commitment, and that this is documented and periodically reassessed in line with CSSF expectations.
- Update board policies to explicitly assign responsibility for strategy, risk appetite, safeguarding of client funds, information security, outsourcing, conflicts of interest and AML/CFT, and ensure these responsibilities are effectively discharged and evidenced.
- Confirm that the institution’s central administration, decision‑making centre and administrative centre are physically located in Luxembourg and that members of the management body are sufficiently present on site, as required under the governance framework.
- Establish or reinforce the “three lines of defence” model by clearly separating business units, control functions (compliance and risk) and internal audit, and ensure reporting lines to the board are independent and robust.
Key Dates
– CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions, electronic money institutions and account information service providers is published
– Decision date of the administrative sanction imposed on members of the board of directors of an electronic money institution
– Application date of CSSF Circular 26/906, from which its governance and risk‑management requirements formally apply to payment institutions and electronic money institutions
– CSSF publicly releases the notice “Administrative sanction of 23 March 2026 – Administrative sanction imposed on the members of the board of directors of an electronic money institution.”
Compliance Impact
Non‑compliance with CSSF governance, safeguarding and AML/CFT expectations can lead to administrative sanctions directly against board members, reputational damage, potential licence constraints and increased supervisory scrutiny. For EMIs and PIs, this raises the risk profile of board roles and makes demonstrable, documented governance and oversight a critical compliance priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintechBank
Administrative sanction imposed on PingPong Europe S.A.
The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.
What Changed
- (From the enforcement notice itself, there are no new rules; the impact is interpretative and enforcement‑related.)
- CSSF confirms that authorised electronic money institutions are subject to active supervisory and enforcement scrutiny, including public administrative sanctions for regulatory breaches.
- The sanction demonstrates that failures which may appear operational or procedural can nonetheless result in monetary fines and public naming, reinforcing the need for robust compliance frameworks in...
- The case is likely to be assessed by CSSF in light of the new governance, risk management and safeguarding expectations introduced under CSSF Circular 26/906 for payment and e‑money institutions,...
- The public nature of the sanction underscores CSSF’s use of transparency as a deterrent tool, increasing reputational risk for firms that do not comply with licensing, governance, reporting or...
Suggested Considerations
- Review the CSSF sanction against PingPong Europe S.A. and identify which categories of requirements (e.g. governance, safeguarding of client funds, reporting, outsourcing, internal controls) were implicated, then map these to your own control framework.
- Conduct a gap analysis against CSSF Circular 26/906, focusing on central administration, internal governance, risk management, and safeguarding of client funds for payment and e‑money institutions.
- Update policies, procedures and internal control documentation governing payment services, e‑money issuance, safeguarding (segregation, reconciliations), outsourcing and IT connectivity to ensure alignment with CSSF Circular 26/906.
- Ensure that a clearly designated member of the management body holds documented responsibility for oversight of safeguarding arrangements and compliance with CSSF requirements for payment and e‑money institutions.
- Implement or enhance daily reconciliations and robust segregation of client funds accounts, supported by periodic internal reviews and testing of safeguarding controls.
Key Dates
– CSSF publishes Circular 26/906 on central administration, internal governance and risk management for payment and e‑money institutions, raising supervisory expectations for the sector
– CSSF issues the administrative sanction decision imposing an administrative fine of EUR 12,000 on PingPong Europe S.A. as an electronic money institution
– Effective date of CSSF Circular 26/906, from which strengthened governance, risk management and safeguarding requirements apply to payment and e‑money institutions
– CSSF publicly publishes the administrative sanction of 2 March 2026, formally informing the market and stakeholders
Compliance Impact
The compliance impact is high for Luxembourg‑authorised payment and electronic money institutions, given the combination of a formal monetary sanction and public disclosure, which increases both regulatory and reputational risk. Continued or serious non‑compliance with governance, safeguarding or reporting obligations could lead to larger fines, restrictions on business, or, in extreme cases, licence withdrawal.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintech
No description available.
What Changed
- - CSSF has published its 2025 supervisory disclosure covering supervisory measures and administrative penalties taken during the year.
- The publication serves as a public register-style disclosure of enforcement outcomes, increasing transparency around CSSF supervision and sanctioning activity.
- A related 2025 CSSF administrative sanction shows that AML/CFT non-compliance can result in a reprimand under the amended Luxembourg AML/CFT Law.
- The 28 July 2025 sanction confirms that CSSF can act where firms fail to maintain adequate professional AML/CFT obligations and related internal controls.
Suggested Considerations
- Review the firm’s AML/CFT control framework against the Luxembourg AML/CFT Law provisions that can trigger CSSF reprimands or sanctions, including governance, monitoring, and escalation controls.
- Verify that suspicious activity detection, investigation, and escalation procedures are documented, implemented, and tested for effectiveness.
- Reassess whether internal controls are sufficient to demonstrate timely compliance with professional AML/CFT obligations under CSSF supervision.
- Update remediation tracking to ensure supervisory findings are closed out promptly and supported by evidence of corrective action.
- Brief senior management on the reputational impact of public supervisory disclosures and ensure that recurring weaknesses are escalated to the board.
Key Dates
- CSSF’s supervisory disclosure covers **measures and administrative penalties for the year 2025**
- CSSF published the prior year’s supervisory disclosure page referencing the **2024** measures and penalties, showing the annual disclosure cycle
- CSSF issued an **administrative sanction** in an AML/CFT case, imposing a reprimand for non-compliance with the AML/CFT Law
Compliance Impact
The compliance impact is material because CSSF enforcement disclosures can expose weaknesses to the market, counterparties, auditors, and other regulators, creating reputational and supervisory pressure. Non-compliance with AML/CFT obligations can lead to public reprimands and potentially more severe measures if deficiencies persist or are systemic.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerBroker Dealer Administrative sanction imposed on Stonehage Fleming Luxembourg S.A.
The CSSF has announced that an **administrative sanction was imposed on Stonehage Fleming Luxembourg S.A. on 5 March 2026**, but it has not yet published the underlying decision or grounds. For compliance teams, this signals that the CSSF continues to actively use sanctions against Luxembourg wealth/asset management entities and that a detailed decision is likely forthcoming, which may contain important precedents on governance, AML/CFT or conduct requirements.
What Changed
- At this stage, based on the CSSF notice alone, no new legal or regulatory requirements are introduced; the publication is a transparency notice that a sanction decision exists.
- the Law of 5 April 1993 on the financial sector (LFS), the Law of 17 December 2010 on undertakings for collective investment, the Law of 12 July 2013 on AIFMs, and the Law of 12 November 2004 on the...
- the CSSF’s established practice of publishing individual sanction decisions, which typically detail shortcomings in organisational requirements, internal controls, oversight of delegates, conduct of...
- the legal provisions breached (for example, Articles 109–111 and 148 of the Law of 2010 or Articles 2-2, 3 and 8-4 of the AML/CFT Law, by analogy with other CSSF sanctions),
- the factual deficiencies identified (e.g., weaknesses in governance, delegate oversight, AML risk assessment, customer due diligence), and
Suggested Considerations
- Monitor the CSSF website for publication of the detailed PDF decision relating to the administrative sanction of 5 March 2026 against Stonehage Fleming Luxembourg S.A.
- Once available, review the full decision to identify the specific legal bases (e.g. LFS, Law of 2010, Law of 2013, AML/CFT Law) and control failures cited by the CSSF.
- Map the identified weaknesses from the decision against your firm’s governance, internal control, delegate oversight and AML/CFT frameworks to identify any similar risk areas.
- Update internal compliance risk assessments to reflect the enforcement themes highlighted in this and recent CSSF sanctions, including the weighting of enforcement risk for organisational and AML/CFT deficiencies.
- Review and, where necessary, strengthen board and senior management oversight arrangements, including the documentation of decisions, challenge and escalation processes, in anticipation of CSSF expectations evidenced in the forthcoming decision.
Key Dates
- CSSF imposes the administrative sanction on Stonehage Fleming Luxembourg S.A. (date of decision)
- CSSF publicly announces the administrative sanction and the existence of a PDF decision (date of publication on CSSF website)
Compliance Impact
The specific financial and qualitative impact of this particular sanction is not yet public, but recent CSSF cases show that deficiencies in governance, delegate oversight and AML/CFT controls can lead to significant fines, public censure and supervisory follow-up. Non-compliance increases the likelihood of intrusive inspections, remediation programmes under CSSF scrutiny, and reputational risk with clients and counterparties.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Wealth ManagerAsset ManagerFamily Office
Administrative sanction imposed on a registered alternative investment fund manager
The CSSF has published an administrative sanction dated 17 April 2026 imposed on a **registered alternative investment fund manager (registered AIFM)**, but the public notice contains no detail on the nature of the breach, legal basis, or penalty level, which are presumably only available in the linked PDFs. For compliance teams, this is another data point that the CSSF is actively enforcing the AIFMD and related Luxembourg implementing laws against even registered (sub‑threshold) AIFMs, not only fully authorised managers.
Because the body text and PDFs are not accessible from the prompt, the analysis below focuses on the **regulatory framework and typical CSSF enforcement themes** that are most likely relevant, and how compliance teams at AIFMs should respond.
---
What Changed
- There are no formal rule changes announced in the short notice itself; however, the enforcement action reinforces several practical expectations that compliance teams should treat as de‑facto...
- CSSF confirms that registered alternative investment fund managers are fully subject to Luxembourg’s AIFM framework, including the Law of 12 July 2013 on alternative investment fund managers and the...
- CSSF reiterates, through enforcement practice, that registration status (sub‑threshold AIFM) does not shield managers from administrative sanctions where organisational, conduct, reporting, or...
- CSSF continues its policy of public naming and shaming through publication of administrative sanctions, signalling that reputational impact is a key component of its deterrence strategy.
- The sanction underscores the CSSF’s readiness to use its full sanctioning toolkit under the AIFM Law, which can include monetary fines, public statements, and prohibitions or restrictions on...
Suggested Considerations
- Obtain and review the full CSSF sanction decision PDFs published with the 17 April 2026 administrative sanction to identify the specific legal provisions, facts and control failures cited.
- Map the identified breaches (e.g. governance, risk management, reporting, valuation, delegation, marketing, or conduct of business) against your firm’s current policies and procedures under the Law of 12 July 2013 on AIFMs and the AIFMD framework.
- Perform a targeted gap analysis for registered AIFMs, focusing on whether “light” registration has led to under‑resourced compliance, risk, valuation, or reporting functions that could attract similar enforcement.
- Review and, where necessary, update internal governance arrangements, including board oversight, documented decision‑making, and escalation processes for regulatory issues, to align with CSSF expectations evidenced in recent sanctions against AIFMs and management companies.
- Test the effectiveness of regulatory reporting and disclosure processes (including Annex IV reporting, investor disclosures, periodic reporting, and prospectus/issuing document accuracy) to ensure they are complete, timely and consistent with CSSF rules.
Key Dates
- CSSF adopts an administrative sanction decision against a registered alternative investment fund manager
- CSSF publishes the administrative sanction notice on its website, including links to the detailed sanction decision in PDF form
Compliance Impact
The compliance impact is medium to high: while the publication does not create new rules, it underscores that the CSSF will actively sanction even registered AIFMs and publicly disclose those sanctions, increasing both regulatory and reputational risk for weakly controlled managers. Firms that treat registration as a “lighter” supervisory regime without proportionate controls are particularly exposed to similar action.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundWealth Manager
1° amending:(a) the Law of 5 April 1993 on the financial sector, as amended;(b) the Law of 17 December 2010 relating to undertakings for collective investment, as amended;(c) the Law of 18 December 2015 on the failure of credit institutions and certain investment firms, as amended;(d) the Law of 15 March 2016 on OTC derivatives, central counterparties and trade repositories and amending different laws relating to financial services, as amended;2° transposing:(a) Directive (EU) 2024/1619 of th...
Bank
This report has been prepared by the SSM Network of Enforcement and Sanctions Experts to present comprehensive statistics on sanctioning activities carried out in 2025 by the ECB and the national competent authorities (NCAs) of European Union (EU) Member States participating in the Single Supervisory Mechanism (SSM) in relation to breaches of prudential requirements.
All Firms
Administrative sanction imposed on BigRep SE
The CSSF imposed a €20,000 administrative fine on BigRep SE on 1 April 2026 for failing to comply with a CSSF order to publish, disseminate, store on the Officially Appointed Mechanism (OAM), and file its half-yearly financial report as of 30 June 2025, under the Luxembourg Transparency Law of 11 January 2008. This sanction underscores CSSF's strict enforcement of periodic disclosure obligations for issuers with Luxembourg as their home Member State, signaling heightened supervisory scrutiny on timely reporting.
What Changed
This is not a regulatory change but an enforcement action under the existing amended Law of 11 January 2008 on transparency requirements for issuers (Transparency Law). Key requirements reiterated include Article 4 (obligation to publish half-yearly financial reports), effective dissemination, storage on the OAM, and filing with CSSF, with CSSF empowered under Article 25(1) to impose fines for non-compliance, considering circumstances per Article 26a. This follows a prior €10,000 fine on the same issuer on 12 January 2026 for initial failure to publish the same report.
Suggested Considerations
- Issuers must ensure timely publication of periodic financial reports (half-yearly per Article 4, annual per Article 3) via effective dissemination, OAM storage (e.g., Luxembourg Stock Exchange systems), and CSSF filing.
- Respond promptly to any CSSF orders or injunctions to avoid escalated fines.
- Implement robust internal controls for reporting calendars, including automated reminders and pre-verification processes.
- Review and file any overdue reports immediately upon CSSF notification.
Key Dates
- Reference date for BigRep SE's half-yearly financial report that was not published
- Date of initial €10,000 fine for failure to publish the report
- Date of €20,000 fine for non-compliance with CSSF order on report dissemination, OAM storage, and CSSF filing
- Deadline to lodge appeal with the Tribunal administratif (three months from 1 April 2026 sanction, per Article 27)
Compliance Impact
Urgency: Medium – This enforcement highlights CSSF's proactive verification of disclosures and willingness to impose escalating fines (€10k initial, €20k for non-response, up to €40k in similar cases), but applies to specific non-compliance rather than new rules. It matters for Luxembourg-domiciled issuers as it demonstrates low tolerance for delays, potentially increasing audit focus on reporting processes and reputational risk from public sanctions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
Administrative sanction imposed on a réviseur d’entreprises agréé
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-delegable professional duties.
What Changed
This is not a regulatory change or new requirement but an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 on the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education.
Suggested Considerations
- Immediate self-audit: Statutory auditors must verify personal compliance with continuing education hours under CSSF Regulation N°16-10, documenting hours against Article 3(1) requirements and submitting evidence if requested.
- Remediation plan: If shortfalls identified, complete deficit training promptly and notify CSSF of corrective measures, as seen in related governance cases where entities implemented remediation.
- Internal training programs: Audit firms should enhance monitoring of auditor CPE (continuing professional education) logs, integrating CSSF controls akin to Article 10 of the Audit Law.
- Fit-and-proper reviews: Boards and compliance officers assess auditor qualifications, escalating any gaps to CSSF per professional obligations.
- Record retention: Maintain verifiable CPE records for at least the reference period plus CSSF inspection windows (typically 3-5 years).
Key Dates
- Likely reference period end for continuing education non-compliance (inferred from identical prior case)
- Date of administrative sanction imposition by CSSF
- Publication date of the sanction notice (today's date, aligning with CSSF practice for transparency under Article 48(2) of the Audit Law)
Compliance Impact
Urgency: Medium. This matters as a signal of CSSF's proactive controls on auditor CPE, with fines starting at EUR 1,500 for initial breaches but scaling with severity/duration; repeated actions (e.g., multiple 2025 sanctions) indicate rising enforcement tempo, risking broader audit ecosystem scrutiny. Affected parties face direct fines and reputational harm, while others must prioritize CPE to avoid chain-reaction liabilities in financial reporting.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
Administrative sanction imposed on a réviseur d’entreprises agréé
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-compliance with minimum continuing education hours.
What Changed
No new regulatory changes are introduced; this is an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 concerning the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education for statutory auditors. Breaches typically involve failing to meet the minimum total hours of continuing education by the reference period end (e.g., December 31, 2024, as in a comparable August 2025 case).
Suggested Considerations
- Statutory auditors must immediately verify compliance with Article 3(1) of CSSF Regulation N°16-10, ensuring minimum continuing education hours are met for relevant periods.
- Audit firms should conduct internal audits of training logs and implement remediation plans, including supplementary training if deficits exist.
- All affected parties must report any identified breaches to CSSF proactively and retain evidence of corrective actions, as CSSF controls under Article 10 of the Audit Law can trigger fines.
Key Dates
- Reference period end for continuing education compliance (inferred from similar case)
- Date of administrative sanction imposition by CSSF
- Publication date of the sanction notice
Compliance Impact
Urgency: Medium. This matters due to the pattern of CSSF enforcement on audit continuing education (e.g., EUR 1,500 fine in August 2025 case for similar breaches), signaling ongoing supervisory controls that could expand to on-site inspections. Non-compliance risks fines, public naming (or anonymous publication per Article 48(2) Audit Law), and reputational damage, but lacks immediate firm-wide deadlines, reducing to medium urgency for proactive reviews.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
Administrative sanction imposed on an investment firm
The CSSF imposed an administrative sanction on 8 October 2025 against an unnamed investment firm, as detailed in a publication released on 4 March 2026. This enforcement action underscores CSSF's rigorous oversight of investment firms, particularly in areas like AML/CFT compliance, conduct rules, and organizational requirements, serving as a warning for similar entities to strengthen cooperation and internal controls. It matters because it highlights escalating fines for repeated or material breaches, potentially influencing supervisory expectations across Luxembourg's financial sector.
What Changed
- No new regulatory changes or requirements are introduced; this is an enforcement action applying existing rules.
- Failure to cooperate with CSSF requests, e.g., not submitting required AML/CFT questionnaires by deadlines, violating Article 5(1) of the amended Law of 12 November 2004 on AML/CFT.
- Non-compliance with investment policies, organizational requirements, or conduct rules under the UCI Law (e.g., Articles 41, 43, 109), including improper broker exposures or valuation failures.
- These reflect ongoing enforcement of established frameworks like the AIFM Law, UCI Law, and AML/CFT Law, with fines calibrated by factors like breach duration, firm size, cooperation level, and prior...
Suggested Considerations
- Enhance cooperation protocols: Implement automated tracking for CSSF requests (e.g., questionnaires) with escalations for reminders; document all responses.
- Review investment compliance: Audit broker exposures, valuation processes, and subscription/redemption controls against UCI Law Articles 41-43, 109; suspend dealings if uncertainties arise.
- Strengthen governance: Conduct gap analyses on internal controls, risk assessments, and reporting for depositary/oversight functions per AIFM Law Article 19(9) and CDR 231/2013.
- Training and monitoring: Roll out firm-wide training on AML/CFT obligations (Article 5(1)) and perform reconciliations of assets/records; prepare for on-site/off-site CSSF inspections.
- Self-reporting: Proactively disclose prior breaches to mitigate fine severity.
Key Dates
- Date of prior depositary oversight fine
- Deadline for submitting CSSF AML/CFT Questionnaire (breach example from similar case)
- Date of fine imposition for UCITS investment policy breaches
- Date of fine imposition in comparable AIFM non-cooperation case
- Date of the sanction in question
Compliance Impact
Urgency: High - This matters due to CSSF's pattern of publicizing nominative sanctions (e.g., Max Gain Capital, Zeus Asset Management), signaling increased scrutiny on investment firms amid AML/CFT and conduct risks. Fines (EUR 10,000–127,500) represent material hits (up to 10% of turnover), with factors like poor cooperation amplifying penalties; firms with similar exposures face elevated inspection risk, especially post-2025 enforcement wave.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerWealth Manager
Administrative sanction imposed on Corestate Capital Holding S.A.
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely for breaches in regulatory compliance such as depositary duties, oversight, or governance under Luxembourg financial laws, marking a repeat enforcement action following a prior sanction in June 2025. This matters for compliance professionals as it underscores CSSF's aggressive enforcement on alternative investment fund managers (AIFMs) and depositaries, signaling heightened scrutiny on safekeeping, oversight, and internal controls to prevent systemic risks in Luxembourg's fund sector. It highlights the regulator's willingness to impose public nominative sanctions, amplifying reputational damage alongside fines.
What Changed
No new regulatory changes or requirements are introduced; this is an enforcement action enforcing existing obligations under laws like the AIFM Law of 12 July 2013 (e.g., Articles 19(8), 19(9), 19(11) on safekeeping and oversight duties), the Law of 5 April 1993 on the financial sector, and Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013, e.g., Articles 92, 94, 96 on risk assessment, valuation verification, and cash flow monitoring).
Suggested Considerations
- Conduct immediate gap analysis: Review safekeeping processes for ownership verification (Article 19(8)(b) AIFM Law), ensuring transaction documentation, segregated account proofs, and full holding chain records are available at transaction points.
- Enhance oversight duties: Implement risk assessments per Article 92(1) CDR 231/2013, valuation compliance checks (Article 94), and cash remittance monitoring (Article 96); appoint delegates with due diligence.
- Strengthen governance: Update internal controls, procedures, and conflict-of-interest policies (e.g., director overlaps); ensure key documentation availability and evidence of controls.
- Firm-wide audit: For repeat offenders like Corestate, perform root-cause analysis on prior sanctions and submit remediation plans to CSSF if inspected.
- Training and reporting: Train staff on CSSF expectations; improve cooperation mechanisms to avoid AML/CFT fines for non-submission of requests.
Key Dates
- Prior administrative sanction imposed on Corestate Capital Holding S.A., indicating ongoing non-compliance issues
- Publication date of the current administrative sanction on Corestate Capital Holding S.A., effective immediately as a public enforcement notice
Compliance Impact
Urgency: High – This represents CSSF's pattern of public nominative fines (e.g., EUR 102,000 on JTC for depositary breaches, EUR 10,000 on Capitalis for AML non-cooperation), with escalation risks for repeat violations like Corestate's back-to-back sanctions. It matters due to Luxembourg's dominance in European fund assets (over EUR 5 trillion), where governance lapses can trigger outflows, license revocation, or cross-border ESMA scrutiny; firms must act preemptively to mitigate fines (typically EUR 10,000–102,000) and reputational harm from nominative publication.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on Corestate Capital Holding S.A.
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely imposing a fine for regulatory breaches, marking a repeat enforcement action following a prior sanction on the same entity dated 20 June 2025. This matters as it underscores CSSF's intensified supervisory scrutiny on Luxembourg-based investment managers, particularly regarding governance, asset safekeeping, and oversight duties under AIFM Law, signaling heightened enforcement risks for similar firms. Compliance teams should review it for patterns in depositary and transparency violations evident in recent CSSF cases.
What Changed
No new regulatory changes or requirements are introduced; this is an enforcement action highlighting non-compliance with existing obligations under Luxembourg's AIFM Law (notably Articles 19(8), 19(9), 19(11), and 51) and related delegated regulations like CDR 231/2013. Key breaches from analogous recent CSSF sanctions include inadequate safekeeping of assets (e.g., missing ownership verification and records), failure to oversee AIFM valuation policies and cash remittance timelines, improper delegation to custodians without due diligence, and weak internal governance such as conflicts of...
Suggested Considerations
- Conduct immediate gap analysis on depositary functions: Verify ownership chains, transaction documentation, segregated account reconciliations, and custodian delegations per AIFM Law Articles 19(8) and 19(11).
- Enhance oversight processes: Implement risk assessments for AIF strategies, valuation policy checks, and cashflow monitoring per CDR 231/2013 Articles 92, 94, and 96.
- Strengthen governance: Review internal controls, procedures, and conflicts (e.g., director overlaps with affiliates); ensure availability of control evidence.
- For issuers like Corestate: Confirm compliance with half-yearly financial reporting and dissemination under Transparency Law Article 4.
- Firm-wide: Perform mock CSSF on-site inspections focusing on 2022-2025 periods, given inspection timelines in recent cases.
Key Dates
- Prior administrative sanction imposed on Corestate Capital Holding S.A
- Publication date of the current administrative sanction on Corestate Capital Holding S.A
Compliance Impact
Urgency: High – This represents repeat enforcement on Corestate (second sanction in under a year), aligning with CSSF's pattern of nominative publications for severe, ongoing breaches in depositary and governance areas, as seen in JTC (EUR 102,000 fine for similar safekeeping/oversight failures) and BigRep SE (EUR 10,000 for reporting lapses). It elevates risks of fines, reputational damage, and market jeopardy assessments under AIFM Law Article 51, urging preemptive remediation amid CSSF's active 2023-2026 inspection cycle.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on Genève Invest (Europe) S.A.
The CSSF imposed an administrative sanction on 23 July 2025 against Genève Invest (Europe) S.A., a Luxembourg-regulated entity, for breaches of professional obligations, as detailed in a publication released on 4 February 2026. This enforcement action underscores the CSSF's focus on robust internal controls and compliance with investment rules, serving as a warning to investment firms on the consequences of organizational and conduct failures. Compliance professionals should note it as evidence of heightened CSSF scrutiny on fund managers handling client assets and counterparties.
What Changed
This is not a regulatory change or new requirement but an enforcement action highlighting existing obligations under Luxembourg law. Key breaches likely mirror patterns in recent CSSF sanctions, such as non-compliance with UCI Law provisions on investment policies (e.g., Articles 41, 43), sound accounting procedures (Article 109), and rules of conduct (Articles 111, CSSF Regulation 10-04), including improper cash deposits with unauthorized brokers and inaccurate asset valuation.
Suggested Considerations
- Immediate review of counterparty due diligence: Verify licenses and financial stability of brokers/prime brokers; cease deposits with unauthorized or suspended entities per UCI Law Article 41.
- Enhance valuation and accounting controls: Ensure assets (e.g., cash deposits) are valued at probable realization value per Article 28(4) UCI Law and prospectus terms; implement automated monitoring for ongoing compliance.
- Conduct internal audits: Assess organizational requirements, investment policies, and conduct rules (CSSF Regulation 10-04); remediate gaps proactively, as seen in mitigated sanctions for cooperative firms.
- Update governance and reporting: Document risk assessments and report prior breaches to CSSF to demonstrate cooperation, potentially reducing fine severity.
Key Dates
- Date of administrative sanction imposition on Genève Invest (Europe) S.A
- Publication date of the sanction document by CSSF
Compliance Impact
Urgency: High – This sanction, published today (4 February 2026), signals ongoing CSSF off-site and on-site probes into fund operations, similar to fines imposed in July 2025 on Zeus Asset Management (€18,136 for UCI breaches) and a bank (reprimand for AML gaps). It matters due to escalating enforcement—fines calibrated to turnover (e.g., 10% in Zeus case)—and risks of reputational damage, especially for wealth managers with broker exposures. Non-compliance could trigger investigations, as CSSF considers infringement duration, cooperation, and history.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerWealth ManagerAll Firms
Administrative sanction imposed on a registered alternative investment fund manager (“AIFM”)
The CSSF imposed an administrative fine of EUR 10,000 on registered alternative investment fund manager (AIFM) C5 S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties and serves as a warning to supervised entities on the consequences of non-compliance with supervisory requests. It matters because it demonstrates the CSSF's willingness to publish names and impose fines for procedural lapses, potentially signaling increased scrutiny on AIFMs' AML/CFT obligations amid broader regulatory focus on financial crime risks.
What Changed
- This is not a regulatory change or new requirement but an enforcement precedent highlighting existing obligations under the AML/CFT Law:
- Mandatory annual submission of the CSSF financial crime questionnaire by supervised entities, including registered AIFMs, as part of the cooperation duty in Article 5(1).
- Fines determined per Article 8-4(1), (2)(f), and (3)(a), considering circumstances under Article 8-5(1), with publication assessed for proportionality under Article 8-6(1).
No new rules introduced;...
Suggested Considerations
- Immediate verification: Confirm timely submission of 2025 financial crime questionnaire (likely due April 2026 for 2025 data); review internal processes for CSSF reminders and automate alerts.
- Procedural enhancements: Implement robust tracking systems for supervisory questionnaires, designate a responsible senior manager for AML cooperation, and document all responses or justifications for delays.
- Training and testing: Conduct firm-wide training on AML/CFT Law Article 5(1) obligations; perform mock audits of reporting workflows, especially for registered AIFMs managing non-CSSF authorized funds.
- Engagement protocol: Respond promptly to CSSF reminders; request in-person meetings if needed before fines escalate; review cooperation history to mitigate fine severity.
- Policy updates: Align with CSSF Circular 25/894 for expanded AIFM reporting on unauthorized funds (notification within 10 working days for registered AIFMs).
Key Dates
- Deadline for submission of the annual financial crime questionnaire covering the year ending 31 December 2024
- Date CSSF imposed the EUR 10,000 administrative fine on the AIFM for non-submission
- Publication date of the sanction decision
- Publication of the queried sanction notice (noting minor title discrepancy possibly referencing a separate but analogous case).[user provided]
Compliance Impact
Urgency: High – This sanction, though modest at EUR 10,000, exemplifies CSSF's proactive use of fines and public naming for AML reporting failures, with potential for higher penalties up to EUR 500,000 or 0.5% of turnover. It heightens risks for registered AIFMs amid CSSF's 2025-2026 priorities on financial crime, sanctions, and expanded reporting (e.g., Circular 25/894), where procedural lapses can trigger investigations, reputational damage, and barriers to remediation. Firms must prioritize to avoid escalation, especially post-publication on 30 January 2026.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Communiqué
The CSSF's January 2026 enforcement report documents the results of its 2025 examination campaign on 2024 financial and non-financial disclosures by issuers under Luxembourg's Transparency Law. This publication is critical for compliance professionals because it reveals systematic compliance gaps across financial reporting (IFRS), sustainability reporting (ESRS), and Alternative Performance Measures (APMs), with 27% of enforcement decisions resulting in injunctions for non-compliance.
What Changed
- The regulatory landscape has evolved significantly with the introduction of new sustainability reporting requirements:
- ESRS Implementation (First Year): 2024 marked the first full reporting year under the European Sustainability Reporting Standards (ESRS), with the CSSF conducting a fact-finding exercise to assess...
- Taxonomy Disclosures Amendment: On 4 July 2025, the European Commission adopted a Delegated Act amending the Taxonomy Disclosures as part of the Omnibus package, affecting Article 8 of the Taxonomy...
- Double Materiality Assessment (DMA) Focus: The CSSF emphasized the importance of issuers not only disclosing the results of their DMA but also explaining the process itself, including granular...
Suggested Considerations
- *Financial Information (IFRS):
- *Enhanced Note Disclosures: Provide sufficient disaggregation and additional information in financial statement notes for material amounts and variances, particularly where information is not presented on the face of primary statements. The CSSF emphasizes compliance with paragraph 112(c) of IAS 1.
- *Cash Flow Statement Presentation: Ensure cash flows are presented on a gross basis (not net), exclude non-cash transactions, and disclose restricted cash balances with accompanying management commentary as required by paragraph 48 of IAS 7.
- *Segment Reporting Completeness: Clearly disclose all income and expense items in segment reporting, even when not separately provided to or reviewed by the Chief Operating Decision Maker (CODM), if they are included in reported segment results.
- *Going Concern Assessment: Maintain high transparency regarding accounting policies and judgments applied when classifying going concern assumptions.
Key Dates
- CSSF published enforcement priorities press release for FY2024 reporting
- European Commission adopted Delegated Act amending Taxonomy Disclosures (Omnibus package)
- CSSF published full results of fact-finding exercise on ESRS reporting
- CSSF published enforcement results report (current publication)
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
Administrative sanction imposed on BigRep SE
The CSSF imposed a €10,000 administrative fine on BigRep SE on 12 January 2026 for failing to publish its half-yearly financial report as of 30 June 2025, as required under Article 4 of Luxembourg's Transparency Law of 11 January 2008 (as amended). This enforcement action underscores the CSSF's rigorous supervision of periodic disclosure obligations for issuers with Luxembourg as their home Member State, serving as a reminder of the consequences for non-compliance with transparency requirements. Compliance professionals should note this as evidence of ongoing CSSF scrutiny on timely reporting, with potential fines scaled based on circumstances per Article 26a.
What Changed
This is not a regulatory change or new requirement but an enforcement of existing obligations under the Transparency Law of 11 January 2008 (as amended), specifically Article 4, which mandates issuers to publish half-yearly financial reports, including effective dissemination, storage on the Officially Appointed Mechanism (OAM), and filing with the CSSF. No new rules are introduced; the sanction reinforces the unchanged deadlines and processes for periodic information publication, with the CSSF acting under Article 25(2) as the competent authority.
Suggested Considerations
- Issuers: Immediately review internal processes for half-yearly financial reporting to ensure compliance with Article 4, including timely publication, OAM storage, and CSSF filing; conduct gap analyses against Transparency Law deadlines.
- All affected parties: Implement or enhance monitoring calendars for periodic disclosures, with automated alerts for period-ends like 30 June; perform mock filings to test dissemination and storage mechanisms.
- BigRep SE specifically: Consider appeal to Tribunal administratif within 3 months if contesting the fine; remediate the specific non-compliance by publishing the overdue report if not already done.
- wide actions are mandated beyond general adherence, but proactive audits are advisable given CSSF's supervisory focus.
Key Dates
- Period-end date for the required half-yearly financial report that BigRep SE failed to publish
- Date of administrative sanction imposition by CSSF and publication of the decision
(i.e., by 12 April 2026) - Deadline for BigRep SE to lodge a court action with the Tribunal administratif against the sanction, per Article 27 of the Transparency Law
Compliance Impact
Urgency: Medium – This matters as a specific enforcement example in CSSF's ongoing verification of periodic information publication, signaling heightened scrutiny rather than a systemic shift. While the €10,000 fine is modest, it demonstrates fines for even isolated breaches (scaled per Article 26a), potentially escalating for repeats; firms should prioritize reporting calendars to avoid reputational harm and publication of sanctions under Article 26b(1).
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
No description available.
This CSSF publication, dated January 12, 2026, identifies the specific population (likely a firm or individual) subject to an enforcement action, such as an administrative sanction, as part of the CSSF's transparency in supervisory measures. It matters because it signals CSSF's active enforcement priorities, potentially in areas like AML or reporting failures, enabling firms to assess similar risks in their operations and strengthen compliance to avoid parallel actions. Published amid rising focus on financial crime typologies like sexual extortion, it underscores the regulator's commitment to public accountability.
What Changed
No new regulatory changes or requirements are introduced in this publication, as it is an enforcement notice rather than a circular or guideline. It serves as a disclosure of an ongoing or concluded enforcement case, aligning with CSSF's practice of publishing sanction details to deter non-compliance and inform the market, without altering existing rules.
Suggested Considerations
- For the named population: Comply with any sanction terms (e.g., pay fines, implement remediation plans, or cease certain activities), and report to CSSF as required; appeal if applicable under Luxembourg administrative law.
- Update internal policies, train staff on enforcement precedents, and ensure robust reporting under Circular CSSF 19/726 or Transparency Law obligations.
Compliance Impact
Urgency: High – Immediate relevance for the named party facing direct consequences; medium-to-high for peers due to CSSF's pattern of public enforcements signaling heightened scrutiny on financial crime, especially amid rising OCSE/FSEC cases noted in recent CSSF guidance. It matters as it could preview broader supervisory sweeps, impacting reputation, operations, and costs if similar vulnerabilities exist.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
Administrative sanction imposed on the alternative investment fund manager Premium Capital Management (“AIFM”)
The CSSF imposed a €10,000 administrative fine on 11 September 2025 against alternative investment fund manager (AIFM) Premium Capital Management for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties, signaling heightened scrutiny on timely supervisory cooperation amid ongoing AML risks in Luxembourg. Compliance teams should view this as a reminder of the low tolerance for even administrative lapses, with potential for escalated fines in repeat cases.
What Changed
This is not a regulatory change but an enforcement precedent under existing rules: non-compliance with Article 5(1) of the AML/CFT Law, which mandates annual submission of a financial crime questionnaire ("Questionnaire") to the CSSF. The fine was calculated per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a), considering circumstances under Article 8-5(1). Publication followed Article 8-6(1) after a proportionality assessment, confirming no market stability risks.
Suggested Considerations
- Immediately review internal processes for annual Questionnaire submission, ensuring calendar invites and automated reminders for the 4 April deadline (covering prior year-end data).
- Conduct a gap analysis on AML/CFT cooperation obligations under Article 5(1), including response protocols to CSSF reminders or queries.
- Update compliance calendars and train staff on escalation procedures; document all submissions with proof (e.g., timestamps, acknowledgments).
- For AIFMs: Verify CSSF registration status under Article 3(2) of the 12 July 2013 AIFM Law and align with broader AML duties.
- If late, proactively submit overdue items and request meetings if needed, as non-response forfeits mitigation opportunities.
Key Dates
- Reference year-end for the financial crime Questionnaire
- Statutory deadline for Questionnaire submission to CSSF
- Date CSSF imposed the €10,000 administrative fine after non-submission despite reminders
- Publication date of the sanction decision
Compliance Impact
Urgency: Medium – This €10,000 fine for a straightforward reporting failure demonstrates CSSF's willingness to penalize non-cooperation swiftly, even without aggravating factors, but the amount is modest and targeted at administrative breaches. It matters as a warning shot in Luxembourg's AML landscape, where repeated failures could trigger higher fines (up to proportionality limits under Article 8-5), reputational damage via public naming, or supervisory escalations; firms should audit 2025/2026 reporting now to preempt similar actions, especially post-NRA updates.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on the alternative investment fund manager Sunbricks GP S.à r.l. (“AIFM”)
The CSSF imposed a **€10,000 administrative fine on Sunbricks GP S.à r.l.**, an alternative investment fund manager, for failing to submit a mandatory annual financial crime questionnaire by the April 4, 2025 deadline, despite two formal reminders. This enforcement action demonstrates the CSSF's strict approach to cooperation obligations under Luxembourg's anti-money laundering and counter-terrorist financing (AML/CFT) framework and signals that non-submission of required compliance documentation—even without evidence of underlying financial crime—triggers regulatory penalties.
What Changed
- This is not a regulatory change but rather an enforcement action clarifying existing obligations:
- Mandatory Annual Questionnaire Requirement: All professionals supervised, authorized, or registered by the CSSF must submit an annual questionnaire on financial crime by April 4 each year, covering...
- Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT establishes a non-negotiable duty to cooperate with the CSSF, which includes timely submission of requested...
- Administrative Fine Framework: The CSSF applies Article 8-4 of the AML/CFT Law to impose fines for non-compliance, with amounts determined under Article 8-5 based on all relevant circumstances.
Suggested Considerations
- regulated entities must:
- *Establish Calendar Controls: Implement internal compliance calendars flagging the April 4 annual questionnaire submission deadline with sufficient lead time (minimum 4-6 weeks before deadline)
- *Designate Responsible Parties: Assign clear ownership for questionnaire completion and submission, with backup contacts
- *Prepare Documentation: Maintain contemporaneous records of financial crime controls, suspicious activity reporting, and compliance activities throughout the year to support accurate questionnaire responses
- *Monitor Communications: Ensure all CSSF correspondence is tracked and escalated immediately; do not ignore reminder notices
Key Dates
– Annual financial crime questionnaire submission deadline (for year ending December 31, 2024)
– Two reminder notices issued by CSSF to Sunbricks GP
– Administrative fine decision date; questionnaire still not submitted
– Publication date of enforcement decision
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on the alternative investment fund manager Capitalis Premiere Group (“AIFM”)
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) Capitalis Premiere Group on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties, signaling heightened scrutiny on timely supervisory cooperation for Luxembourg-regulated entities. Compliance teams should note this as a low-value but public reminder of potential fines for administrative lapses in AML processes.
What Changed
This is not a regulatory change or new requirement but an enforcement precedent under existing rules: non-compliance with the annual financial crime questionnaire submission, mandated by Article 5(1) of the AML/CFT Law, triggers fines per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a). The CSSF considered all relevant circumstances under Article 8-5(1) to set the €10,000 fine amount and published the sanction nominatively after proportionality assessment per Article 8-6(1), confirming no market stability risks.
Suggested Considerations
- Ensure timely submission of annual financial crime questionnaires by 4 April each year (for prior calendar year data); implement calendar reminders and escalation processes for CSSF requests.
- Respond promptly to CSSF reminders or queries on AML/CFT compliance to avoid escalation to fines; document any delays with justification evidence.
- Review internal AML cooperation protocols, including governance for questionnaire completion, and train staff on Article 5(1) obligations; consider requesting in-person meetings if disputing CSSF demands.
- No retroactive actions needed for this case, but conduct gap analysis on reporting workflows to prevent similar breaches.
Key Dates
- Deadline for submitting the annual financial crime questionnaire covering the year ending 31 December 2024
- Date CSSF imposed the €10,000 administrative fine on Capitalis Premiere Group for non-submission
- Date of CSSF publication of the sanction decision
Compliance Impact
Urgency: Medium - This €10,000 fine is modest but publicly names the firm, amplifying reputational risk in Luxembourg's competitive fund domicile; it matters as a clear CSSF signal of zero tolerance for basic cooperation failures in AML, potentially foreshadowing stricter enforcement amid EU AML harmonization pressures. AIFMs face ongoing annual risk, with non-response despite reminders treated as willful breach; firms with weak reporting controls should prioritize fixes to avoid cumulative fines or escalations.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on the alternative investment fund manager Lion Management (“AIFM”)
The CSSF imposed a €10,000 administrative fine on Lion Management, an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the 4 April 2025 deadline. This enforcement action demonstrates the CSSF's commitment to enforcing cooperation obligations under Luxembourg's anti-money laundering and terrorist financing framework, with direct implications for all AIFMs regarding timely compliance with supervisory reporting requirements.
What Changed
- This is not a regulatory change but rather an enforcement action clarifying existing obligations. However, it reinforces critical compliance requirements:
- Mandatory Annual Questionnaire Submission: All CSSF-supervised professionals, including AIFMs, must submit an annual questionnaire on financial crime by the specified deadline (in this case, 4 April...
- Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing establishes a non-negotiable obligation to cooperate with the...
- Enforcement Escalation: The CSSF will issue reminders before imposing sanctions, but failure to respond to reminders results in administrative fines determined under Article 8-4 of the AML/CFT Law.
Suggested Considerations
- *Establish Calendar Controls: Implement firm-wide systems to track the annual financial crime questionnaire deadline (typically 4 April for the prior calendar year)
- *Designate Responsible Parties: Assign clear ownership for questionnaire completion and submission to the CSSF, with escalation procedures
- *Monitor CSSF Communications: Establish protocols to immediately flag and respond to any CSSF correspondence, including reminders or requests for information
- *Document Submission: Maintain evidence of timely submission (timestamps, confirmation receipts) to demonstrate compliance
- *Escalate Non-Compliance Immediately: If submission cannot be met by deadline, proactively contact the CSSF to explain delays and request extensions rather than ignoring reminders
Key Dates
- Deadline for submission of annual financial crime questionnaire for year ending 31 December 2024
- Date CSSF imposed administrative fine after two reminders went unheeded
- Publication date of the administrative sanction decision
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on the alternative investment fund manager Max Gain Capital S.à r.l. (“AIFM”)
The CSSF imposed a €10,000 administrative fine on Max Gain Capital S.à r.l., an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the April 2025 deadline. This enforcement action demonstrates the CSSF's active monitoring of AML/CFT compliance obligations and its willingness to sanction non-cooperation, even for procedural failures unrelated to substantive money laundering violations.
What Changed
- This is not a regulatory change but rather an enforcement action clarifying existing obligations:
- Mandatory Annual Questionnaire Requirement: All CSSF-supervised professionals must submit an annual questionnaire on financial crime covering the preceding calendar year.
- Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT imposes a non-negotiable duty to cooperate with CSSF supervisory requests.
- Enforcement Escalation: The CSSF will issue reminders before imposing sanctions, but continued non-compliance triggers administrative fines under Article 8-4 of the AML/CFT Law.
Suggested Considerations
- regulated entities must:
- *Identify Reporting Obligations: Confirm whether your firm is subject to the annual financial crime questionnaire requirement under Article 5(1) of the AML/CFT Law
- *Calendar Management: Establish internal processes to ensure questionnaires are submitted by 4 April each year for the preceding calendar year
- *Documentation: Maintain records demonstrating timely submission and preserve evidence of compliance
- *Escalation Protocol: If unable to meet deadlines, proactively contact the CSSF to request extensions or clarification rather than ignoring reminders
Key Dates
- Deadline for submission of financial crime questionnaire for the year ending 31 December 2024
- CSSF issued two reminders to Max Gain Capital after the missed deadline
- CSSF imposed the €10,000 administrative fine
- CSSF published the administrative sanction decision
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on the alternative investment fund manager Agriland Management S.A. (“AIFM”)
The Commission de Surveillance du Secteur Financier (CSSF), Luxembourg's financial regulator, imposed a **EUR 10,000 administrative fine on Agriland Management S.A.**, an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the April 2025 deadline. This enforcement action demonstrates the CSSF's commitment to enforcing cooperation obligations under Luxembourg's anti-money laundering and terrorist financing (AML/CFT) framework and signals heightened scrutiny of compliance with supervisory reporting requirements.
What Changed
- This is not a regulatory change but rather an enforcement action that clarifies existing obligations:
- Mandatory Annual Reporting: All CSSF-supervised professionals must submit an annual questionnaire on financial crime by 4 April each year, covering the preceding calendar year.
- Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT establishes a non-negotiable duty to cooperate with the CSSF, including timely submission of requested...
- Enforcement Escalation: The CSSF will issue reminders for non-compliance, but continued failure to respond triggers administrative sanctions without requiring evidence of intentional misconduct.
Suggested Considerations
- *Establish Reporting Calendars: Implement systems to track the 4 April annual deadline for financial crime questionnaire submissions
- *Designate Responsible Personnel: Assign clear accountability for completing and submitting the questionnaire to the CSSF
- *Respond to Regulatory Requests: Do not ignore CSSF reminders; engage proactively, including requesting in-person meetings if clarification is needed
- *Document Justifications: If unable to meet deadlines, provide written evidence explaining the delay and proposed remediation timeline
- *Monitor Supervisory Communications: Establish procedures to ensure regulatory correspondence is tracked and escalated appropriately
Key Dates
– Deadline for submission of financial crime questionnaire for year ending 31 December 2024
– Two reminder notices issued by CSSF to Agriland Management S.A
– Administrative fine imposed
– Sanction published by CSSF
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Administrative sanction imposed on the alternative investment fund manager Bedrock I GP S.à r.l. (“AIFM”)
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) Bedrock I GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of AML reporting duties and serves as a public warning to supervised entities on timely supervisory compliance. It matters because it demonstrates that even modest fines are pursued for basic reporting lapses, potentially signaling heightened scrutiny on AIFMs' AML processes amid ongoing regulatory focus on financial crime risks.
What Changed
This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing (AML/CFT Law). Specifically, it reaffirms the mandatory annual submission of the CSSF's financial crime questionnaire ("Questionnaire") by supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, as part of the cooperation duty in Article 5(1).
Suggested Considerations
- Immediately verify submission status of the 2024 Questionnaire (or any outstanding); if overdue, submit promptly with justification to mitigate further escalation.
- Implement automated calendar alerts and internal workflows for all CSSF reporting deadlines, including annual AML/CFT Questionnaire.
- Conduct a compliance gap analysis on cooperation obligations under Article 5(1) AML/CFT Law, documenting reminder responses and evidence retention.
- Train senior managers and compliance teams on supervisory interactions, including rights to request in-person meetings before fines.
- Review governance for timely escalation of CSSF reminders to decision-makers.
Key Dates
- Reference period end for the Questionnaire covering financial crime compliance
- Statutory deadline for Questionnaire submission to CSSF
- Date of administrative fine imposition (€10,000) after non-submission despite reminders
- Publication date of the sanction decision by CSSF
Compliance Impact
Urgency: Medium - This is a post-facto enforcement on a past breach (2024 reporting cycle), with the €10,000 fine relatively low, indicating proportionality for a first-time or isolated lapse. It matters as a leading indicator of CSSF's 2025-2026 focus on AML cooperation, with multiple similar AIFM sanctions published simultaneously, risking escalated fines or reputational harm for repeat offenders; firms should prioritize reporting hygiene to avoid public naming, which CSSF deems non-disruptive to markets here.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on the alternative investment fund manager C5 Haven Cyber GP S.à r.l. (“AIFM”)
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) C5 Haven Cyber GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of AML reporting duties and serves as a public warning to supervised entities on the consequences of non-cooperation. It matters because it demonstrates that even modest fines will be levied for procedural lapses, potentially signaling increased scrutiny on timely AML compliance submissions amid broader regulatory focus on financial crime risks.
What Changed
- This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended AML/CFT Law:
- Annual Questionnaire Submission: Supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, must submit an annual financial crime questionnaire...
- Fine Provisions: Fines are imposed per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a), with amounts determined by relevant circumstances under Article 8-5(1); publication follows Article 8-6(1) after...
Suggested Considerations
- Immediate Review: AIFMs and similar entities must verify their internal processes for annual Questionnaire submission, ensuring calendar reminders and automated tracking for 4 April deadlines.
- Remediation if Late: Submit overdue Questionnaires promptly with explanations; request in-person meetings if needed, as the sanctioned AIFM failed to do so.
- Process Enhancements: Implement escalation protocols for CSSF reminders, designate a senior compliance officer for oversight, and document all submissions/acknowledgments to demonstrate cooperation under Article 5(1).
- Training: Conduct firm-wide training on AML/CFT cooperation duties, emphasizing that non-response leads to fines without need for justification.
Key Dates
- Reference year-end for the financial crime Questionnaire
- Statutory deadline for submitting the Questionnaire for the year ending 31 December 2024
- Date CSSF imposed the €10,000 administrative fine after noting non-submission despite reminders
- Date of CSSF publication of the sanction decision
Compliance Impact
Urgency: Medium - This is a low-value fine (€10,000) for a procedural breach, not involving substantive AML failures like suspicious transactions or sanctions screening delays seen in higher fines (e.g., €185,000 on Rakuten Bank). It matters as a precedent for CSSF's willingness to publicly name-and-shame for basic non-cooperation, potentially escalating to higher penalties for repeats; with publication on 9 January 2026, firms should prioritize 2025/2026 reporting to avoid similar exposure amid CSSF's active enforcement (3192+ sanctions published).
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on the alternative investment fund manager C5 S.à r.l. (“AIFM”)
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager C5 Haven Cyber GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of reporting duties in AML/CFT compliance, serving as a warning to supervised entities on the consequences of administrative delays. It matters because it highlights low-tolerance for even minor procedural lapses, potentially signaling increased scrutiny on annual reporting amid broader AML/CFT priorities.
What Changed
- This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended AML/CFT Law:
- Article 5(1) mandates supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, to cooperate fully with CSSF, including submitting the annual financial crime...
- Breach occurred due to non-submission of the 2024 year-end Questionnaire, with fine determined per Articles 8-4(1), 8-4(2)(f), 8-4(3)(a), and 8-5(1).
- Publication of the sanction follows Article 8-6(1), after proportionality assessment to avoid market stability risks.
No new rules introduced; reinforces ongoing duty to meet CSSF reporting timelines...
Suggested Considerations
- Review and confirm timely submission of all pending or future CSSF financial crime questionnaires; establish automated calendar reminders for annual deadlines (e.g., 4 April for prior year-end data).
- Implement escalation protocols for CSSF reminders, ensuring immediate response and submission within days, not weeks.
- Conduct internal audit of AML/CFT cooperation obligations, documenting justifications for any delays and preparing evidence for potential CSSF hearings or meetings.
- Update compliance policies to prioritize Article 5(1) duties, including training for responsible persons on fine risks under Article 8-4.
- For AIFMs: Verify alignment with Article 3(2) of AIFM Law and integrate questionnaire processes into governance frameworks.
Key Dates
- Deadline for submission of financial crime Questionnaire covering year ending 31 December 2024
- Date CSSF imposed €10,000 administrative fine on C5 Haven Cyber GP S.à r.l. for non-submission despite reminders
- Date of CSSF publication announcing the sanction
Compliance Impact
Urgency: Medium - Matters due to CSSF's demonstrated willingness to impose and publicize fines for straightforward reporting failures, even at €10,000, which could escalate for repeat or severe cases; acts as a precedent amid rising AML/CFT enforcement (e.g., larger fines like €214,000 in similar contexts). Firms delaying submissions risk reputational damage from nominative publications under Article 8-6(1), market confidence erosion, and cumulative penalties; proactive remediation now prevents higher scrutiny in upcoming inspections.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge Fund
Administrative sanction imposed on JTC (Luxembourg) S.A.
The CSSF imposed a €102,000 administrative fine on JTC (Luxembourg) S.A. on 23 July 2025 for breaches in its professional obligations as a depositary of non-financial assets under the AIFM Law, identified during an on-site inspection from February 2023 to January 2024 covering activities up to December 2022. This enforcement action highlights CSSF's scrutiny of depositary functions, particularly risk assessment and oversight controls, serving as a warning for similar entities to strengthen compliance amid rising supervisory focus on AIFM depositaries.
What Changed
This is an enforcement action, not a regulatory change; it enforces existing requirements under Article 51(1) (1st and 7th indents) and Article 51(2) (1st sub-paragraph, 3rd indent) of the amended Law of 12 July 2013 on AIFMs (AIFM Law), and related provisions like Article 92(1) of Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013).
Suggested Considerations
- related entities) must:
- Conduct immediate gap analyses on risk assessment processes for AIF strategies and AIFM organization per Article 92(1) CDR 231/2013.
- Implement robust verification processes for AIFM compliance with asset delegation rules.
- Ensure availability of key documentation and evidence of controls for the depositary function, addressing pre-2022 gaps if applicable.
- Develop and test oversight processes, leveraging self-identified improvements and action plans as mitigating factors, as JTC did prior to inspection.
Key Dates
January 2024; Period of CSSF on-site inspection on depositary obligations, covering activities up to December 2022
Date CSSF imposed the €102,000 administrative fine on JTC (Luxembourg) S.A
Date of official CSSF publication announcing the sanction
Compliance Impact
Urgency: High – This matters due to the fine's size (€102,000), reflecting breach accumulation, severity, and duration, despite JTC's partial remediation; it signals intensified CSSF on-site scrutiny of depositary functions post-2023 inspections, with potential for higher penalties absent proactive controls. Depositaries face elevated enforcement risk, especially with unavailability of evidence pre-2022, urging swift remediation to avoid similar outcomes under Article 51 AIFM Law.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)
Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.
What Changed
- - Institutions must develop, implement, and maintain up-to-date policies, procedures, and controls for identifying, investigating, and applying restrictive measures without delay, including risk...
- Management body responsibilities expanded: approve sanctions compliance strategy, oversee implementation, conduct at least annual assessments of exposure and controls, ensure remedial actions, and...
- Screening and monitoring requirements: Maintain updated sanctions lists with immediate integration of changes; screen customer base, transactions, and datasets accurately; enable immediate...
- Training and testing: Deliver regular, documented role-specific training; perform ongoing system testing for screening calibration, list accuracy, transaction monitoring effectiveness, and reporting.
- Proportionality applies based on institution's size, activities, and exposure; PSPs and CASPs explicitly addressed with tailored controls.
Suggested Considerations
- Conduct annual exposure assessments to sanctions risks and circumvention; update policies accordingly.
- Appoint senior management/board-level responsibility for approving and overseeing sanctions strategy, including annual reviews and deficiency reporting.
- Implement reliable screening systems for customers, transactions, and lists; define screenable datasets; test systems regularly for effectiveness (e.g., immediate freezing, accurate hits).
- Provide documented training to relevant staff on sanctions, institutional exposure, and internal processes.
- Establish processes for immediate action on matches: suspend transfers, freeze assets, report to Ministry of Finance/CSSF/FIU without delay; maintain whitelists only under strict conditions.
Compliance Impact
Urgency: High – With less than 12 months until the 30 December 2025 deadline (as of January 2026), firms face binding requirements for absolute compliance, including personal accountability for management bodies; non-compliance risks enforcement by CSSF, reputational damage, and fines amid frequent EU sanctions updates (e.g., Regulations 2025/1469, 2025/1476). This elevates sanctions from operational task to strategic board priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange